8Base is a financially motivated ransomware and extortion operation that became highly visible in 2023 and is widely associated with customized use of Phobos ransomware. Reporting links the group’s malware and ransom-note conventions to Phobos, while its leak-site presentation and extortion messaging have shown notable similarities to RansomHouse. 8Base has conducted double-extortion operations, stealing data prior to encryption and publishing victim information on a dedicated leak site. Some reporting also indicates the group’s leak infrastructure has been used to publish data obtained by Phobos affiliates, suggesting overlap with the broader Phobos ecosystem. Observed 8Base intrusions have used commodity malware and access tooling including SmokeLoader and SystemBC, and incident-response reporting has documented post-compromise activity such as credential dumping, PowerShell execution, token abuse, privilege escalation, and installation of remote administration software for persistence and access retention. Malware analysis of 8Base samples shows typical ransomware behaviors including persistence establishment, shadow-copy and backup deletion, disabling recovery mechanisms and firewall protections, drive and file enumeration, and file encryption using Phobos-derived logic. Victimology appears opportunistic across multiple sectors rather than narrowly focused, with reporting describing broad industry impact and a significant number of victims in Western countries. Japanese organizations and overseas subsidiaries of Japanese firms have also appeared prominently in public victim reporting, including a 2024 incident affecting Nidec’s Vietnam-based division that was claimed by both 8Base and Everest. 8Base has also been cited among the leading ransomware actors leaking Japanese organizations over a multi-year period. The identities behind 8Base remain unclear. Public reporting has not established a definitive operational relationship between 8Base and RansomHouse, nor fully resolved whether 8Base is an independent group, a Phobos affiliate cluster, or a branding layer used by experienced operators within that ecosystem. Known aliases include 8base_ransomware_actors.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
23 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
3 malware families attributed to this actor across reporting.
19 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Mentioned only as one of the groups that claimed responsibility for a separate 2024 ransomware attack against another Nidec division.
Named as one of the ransomware groups publicly linked to Woodgnat as a downstream partner or affiliate receiving sold access.
Previously claimed a separate ransomware-related extortion incident involving Nidec's Vietnam-based Nidec Precision division in 2024.
Named as a ransomware group linked to the malware activity.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.